Email spam filter not working is frustrating for two very different reasons: unwanted messages may be flooding your inbox, or important messages may be disappearing into Spam, Junk, or quarantine. The fastest fix is to identify where the message was classified and moved before changing settings at random.

This guide covers both sides of the problem. First, it helps recipients stop spam that reaches the inbox and recover legitimate mail. Then it shows senders how to fix messages that are being mislabeled as spam by Gmail, Outlook, Yahoo, iCloud, or a business mail gateway.

Start by defining what “not working” means

A spam filter is not one switch. A message can be handled by several independent layers:

  1. The receiving provider’s spam, phishing, malware, and bulk-mail detection.
  2. Organization-wide security policies, especially in Microsoft 365 or Google Workspace.
  3. A mailbox’s Safe Senders, Blocked Senders, Junk, or Spam settings.
  4. Inbox rules and filters that label, archive, delete, forward, or move mail.
  5. A desktop or mobile mail app’s local junk-mail rules.

That distinction matters. If obvious spam arrives in your inbox, the provider may have classified it as legitimate, or a rule may have moved it back. If a legitimate invoice lands in Junk, the provider may have made a false-positive decision, a security policy may have quarantined it, or the sender may have failed authentication.

Before changing anything, choose the symptom that matches your case:

  • Spam reaches the inbox: focus on reporting, blocking, inbox rules, and account security.
  • Real mail reaches Spam/Junk: focus on marking it “not spam,” Safe Senders, sender authentication, and administrator policies.
  • Mail vanishes completely: look for Trash, Archive, forwarding, quarantines, and mail-flow logs.
  • A rule or filter does nothing: verify the exact matching condition, conflicting rules, and whether the message arrived after the rule was created.

Gmail filters can label, archive, delete, star, or forward incoming messages, while Microsoft 365 and Outlook can apply mailbox safelists and organization-level anti-spam actions. Those actions can overlap, so a visible inbox result is not always evidence of the first rule that ran. (support.google.com)

Run the five-minute diagnosis before changing settings

Do this with one specific message that was handled incorrectly. Do not start by deleting filters or adding dozens of blocked addresses; that makes it harder to establish the cause.

1. Find the message everywhere

Search All Mail, Spam/Junk, Trash/Deleted Items, Archive, and any custom folders or labels. In a work account, ask an administrator to check quarantine too. Microsoft 365 can quarantine unwanted or dangerous messages rather than place them in Junk, and some categories such as malware or high-confidence phishing cannot simply be turned into normal inbox delivery. (learn.microsoft.com)

2. Check whether it is one sender or a pattern

One sender repeatedly reaching the inbox often calls for a block or a narrow rule. Many unrelated spam messages reaching the inbox suggests a provider-level classification issue, an account setting problem, or a phishing campaign with changing sender addresses.

Conversely, one trusted sender repeatedly going to Spam points to that sender’s authentication, domain, content, sending infrastructure, or reputation. If many legitimate senders are being junked, investigate your mail client, mailbox safelist, and organization-wide security policy first.

3. Record the message facts

Create a short troubleshooting note with:

  • Date and approximate delivery time.
  • Recipient address.
  • Visible From: address and domain.
  • Subject line.
  • Folder where it landed.
  • Whether it was expected, spam, promotional, or phishing.
  • Any rule that you believe should have matched.
  • A copy of the full message headers if you administer the mailbox or sending domain.

This turns “the spam filter is broken” into a testable claim. Gmail lets recipients view Show original and analyze the full header with Google Admin Toolbox Messageheader. Microsoft 365 adds anti-spam and authentication information to message headers, including Authentication-Results, X-Forefront-Antispam-Report, and X-Microsoft-Antispam. (support.google.com)

4. Use a fresh test message

Rules normally affect new mail; they do not reliably repair a message that has already been delivered. Send a new, plainly identifiable test such as Filter test 2027-04-01 1030 from the relevant sender. Then check where it lands before modifying another setting.

5. Test one change at a time

If you add a sender to a safe list, create a rule, and change a global anti-spam policy all at once, you cannot know which action solved—or caused—the result. Make one change, send one fresh test, then keep or reverse that change based on the outcome.

If spam is reaching your inbox

The right response depends on whether the mail is unsolicited marketing, obvious spam, or an attempt to steal credentials or payment details.

Report spam instead of only deleting it

For ordinary unwanted mail, use your provider’s Report spam or Junk command. In Gmail, reporting spam moves the message to Spam, and Google says it may analyze reported mail to improve protection against spam and abuse; repeated reports help Gmail identify similar messages more efficiently. (support.google.com)

Reporting is more useful than merely deleting because deletion tells the service only that the message is gone. A spam report provides a classification signal. Still, do not open links, download attachments, or reply merely to report a suspicious email.

For messages impersonating a bank, coworker, software vendor, or delivery service, use Report phishing where available. Gmail separately supports phishing reports because phishing is a deceptive attempt to steal information or gain access to accounts. (support.google.com)

Block stable senders, not every new alias

Block a sender when the unwanted mail consistently comes from the same address or recognizable domain. In Gmail, blocking an address sends future messages from that sender to Spam. (support.google.com)

Do not expect address blocking to solve a campaign that rotates through newly created addresses. In that situation, reporting a representative sample and using a content-based rule is usually more practical than maintaining a huge block list.

Use a narrow rule for repeated, recognizable junk

A good rule targets something stable that the attacker or marketer is unlikely to change. Examples include a distinct sender domain, an unusual phrase used in every message, or a recipient alias that exists only for one site.

Avoid broad rules such as:

  • “Delete every message containing invoice.”
  • “Send all mail with an attachment to Spam.”
  • “Delete messages from any address outside my company.”
  • “Filter every subject containing urgent.”

Those conditions catch legitimate mail often enough to create a second, more damaging problem: silent data loss.

Unsubscribe only when the sender is legitimate

Use unsubscribe links for newsletters, stores, and services you recognize and trust. Do not use an unsubscribe link in an obvious scam, because interacting may confirm that your address is active or take you to a malicious site.

Gmail also has subscription-management features for recognized mailing lists. Its help documentation notes that, after you unsubscribe through that interface, new mail from the sender goes to Spam. (support.google.com)

Fix Gmail spam filters and Gmail rules

Gmail has two systems people often confuse:

  • Spam classification, which decides whether a message belongs in Spam.
  • Filters, which apply actions when messages match search-style conditions.

A Gmail filter is best for organizing known mail or setting a deterministic action for a clear pattern. It is not a full replacement for Gmail’s threat detection.

Stop trusted mail from going to Gmail Spam

For a sender you trust, first open the message in Spam and select Not spam. Gmail says that removing a message from Spam helps ensure future mail from that sender does not go there; adding the sender to Google Contacts and creating a specific filter are additional options. (support.google.com)

Then create a narrow filter in Gmail on the web:

  1. Open Gmail and select the search-options icon in the search bar.
  2. In From, enter the full address, such as billing@vendor.example, or a domain pattern if appropriate.
  3. Select Create filter.
  4. Choose the action you need, such as Never send it to Spam, Apply the label, or Mark as important.
  5. Create the filter and send or wait for a new message to test it.

Gmail’s documented filter workflow is browser-based and supports actions including labels, archive, deletion, starring, and forwarding. Filters apply to new matching mail; when a forwarding filter is created, for example, Google explicitly notes that only new messages are affected. (support.google.com)

Stop a Gmail filter from missing messages

If a filter appears not to work, check these points in order:

  1. Confirm the filter matches the actual address. The visible display name is not the same as the sending address. Open the message details and copy the address.
  2. Remove unnecessary conditions. A filter that requires both a sender and an exact subject phrase will not run if either changes.
  3. Check for conflicting actions. An older filter may archive, delete, forward, or label the same mail differently.
  4. Look in All Mail and Trash. A filter may have worked by archiving or deleting the message rather than leaving it in Inbox.
  5. Send a new test. Editing a filter is not proof that it applied to a historical message.
  6. Check delegated access and connected apps. Another user, mobile client, or automation tool may be moving messages after Gmail delivers them.

A safe setup for a critical vendor is usually one exact-address filter with Never send it to Spam and a label such as Vendors/Accounts Payable. A dangerous setup is an all-domain rule that bypasses spam protection for every message from a large third-party domain, because compromised accounts and lookalike subdomains can still deliver harmful mail.

How to confirm Gmail is working again

Success is not “one email showed up.” Send or wait for at least two new, matching messages and confirm that each has the expected label and inbox location. For a sender-side investigation, open Show original and look for spf=pass or dkim=pass; Gmail documents those as authentication indicators. (support.google.com)

Fix Outlook and Microsoft 365 Junk Email problems

Outlook can mean different products: Outlook desktop, Outlook on the web, Outlook.com consumer mail, or a work mailbox hosted in Microsoft 365. The settings and the person who controls them differ.

For an individual Outlook mailbox

Check the Safe Senders and Blocked Senders lists first. Microsoft describes the mailbox safelist collection as the Safe Senders list, Safe Recipients list, and Blocked Senders list. Mail from a blocked sender is classified as spam, while mail from a Safe Sender is delivered to the Inbox under the documented Exchange Online behavior. (learn.microsoft.com)

Also review inbox rules. A seemingly harmless rule such as “move mail containing order to a folder” can catch real receipts, phishing messages, and internal procurement notices alike. Disable suspicious rules temporarily and retest with a new message.

For Microsoft 365 administrators

Do not assume Outlook itself made the classification. Microsoft 365 uses anti-spam policies for inbound protection, and the default policy applies to all recipients unless a higher-priority custom policy matches. Microsoft’s troubleshooting guidance states that only the first matching anti-spam policy—the highest-priority matching policy—applies to a recipient. (learn.microsoft.com)

Use this sequence:

  1. In the Microsoft Defender portal, inspect the affected recipient’s anti-spam and anti-phishing policies.
  2. Check whether a custom policy has higher priority than the default or preset policy.
  3. Search quarantine for the exact sender, recipient, subject, and time window.
  4. Run message trace to establish whether Microsoft 365 received, rejected, deferred, delivered, or rerouted the message.
  5. Open the message headers to inspect the spam verdict and authentication results.
  6. Correct the smallest applicable policy scope, then retest with a fresh message.

Message trace records whether Exchange Online received, rejected, deferred, or delivered a message and shows actions taken before final delivery. A message sent to Junk or quarantine can still appear with a delivered status, so inspect event details rather than treating “Delivered” as proof that it reached the Inbox. (learn.microsoft.com)

What not to do in Microsoft 365

Do not globally allow-list entire consumer domains, disable phishing protection, or automatically release every quarantined message. Broad exceptions trade a short-term mail-delivery convenience for a long-term account-compromise risk.

For a known false positive, scope an exception to a verified sender, recipient group, or controlled business process. Then document an expiry date and review it. If the sender is external, ask them to fix authentication rather than permanently weakening your defenses.

Fix Apple Mail and iCloud Mail junk filtering

Apple Mail on Mac can apply its own junk-mail behavior in addition to the server-side filtering performed by your provider. In Mail on Mac, go to Mail > Settings > Junk Mail and verify that Enable junk mail filtering is selected if your goal is to use the app’s filter. Apple also provides advanced custom junk actions, which should be used cautiously because an overly broad local rule can hide legitimate mail. (support.apple.com)

For an @icloud.com address, check the Junk folder at the iCloud Mail level rather than relying only on the Apple Mail app. Apple says iCloud Mail automatically identifies much junk mail and moves it to Junk; messages in Junk are automatically deleted after 30 days, so review that folder regularly for false positives. (support.apple.com)

Mark incorrectly classified messages as junk or not junk in the same mailbox where they were classified. Apple says that reporting a message as junk helps improve future iCloud Mail filtering. (support.apple.com)

If your own emails are going to Spam

When customers say “your spam filter is not working,” the actual issue may be that your product emails, receipts, password resets, newsletters, or sales messages are landing in their Spam folders. Authentication is the first technical checkpoint, but it is not a guaranteed inbox placement pass.

Separate authentication from reputation and content

Email providers assess more than one signal. Authentication proves that a sender is authorized to use a domain; it does not prove recipients want the mail. A fully authenticated campaign can still be filtered when recipients report it as spam, engagement is weak, mailing practices are poor, or the message resembles abusive mail.

Gmail’s Postmaster Tools dashboards include spam rate, IP reputation, domain reputation, delivery errors, and the percentage of mail passing SPF, DKIM, and DMARC. That makes them useful for distinguishing an authentication failure from a reputation or complaint problem. (support.google.com)

Authenticate every sending stream

Inventory every system that sends mail using your domain:

  • Google Workspace or Microsoft 365 mailboxes.
  • Transactional-email provider.
  • Marketing platform.
  • CRM and support desk.
  • Website contact forms.
  • Billing software.
  • Recruiter, scheduling, or survey platforms.

A common failure is authenticating the marketing tool but forgetting the support platform, or signing mail with one domain while displaying another in the visible From: address.

Google requires all senders to personal Gmail accounts to set up SPF or DKIM. For senders that send more than 5,000 messages per day to Gmail accounts, Google requires SPF, DKIM, and DMARC, plus other requirements such as valid forward and reverse DNS and TLS. Google also requires alignment: for direct mail, the domain in the visible From: header must align with either the SPF domain or DKIM domain. (support.google.com)

Yahoo’s sender guidance similarly calls for SPF or DKIM for all senders and SPF, DKIM, and a valid DMARC policy for bulk senders; it advises keeping spam rates below 0.3%. (senders.yahooinc.com)

Use correct DNS record syntax

Your DNS host publishes these records, but the exact DKIM value and SPF include mechanism must come from each mail provider. Never paste a provider example blindly, and never create multiple SPF TXT records for the same domain.

Here is illustrative syntax only for example.com—a reserved example domain, not a configuration to copy into production:

example.com. TXT "v=spf1 ip4:203.0.113.25 -all"
selector1._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY_FROM_PROVIDER"
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r"

SPF authorizes sending hosts through a DNS TXT record. DKIM adds a verifiable signature, using a public key published in DNS. DMARC lets a domain owner publish handling preferences for mail that fails aligned authentication and request reports. (datatracker.ietf.org)

Start DMARC at p=none while you inspect reports and discover every legitimate sender. Move to p=quarantine or p=reject only after all legitimate streams pass alignment consistently. A stricter DMARC policy without a complete sender inventory can break mail sent by an overlooked vendor.

If you need help mapping a sending service’s DNS records, consult its official documentation and your email API setup guides before changing production DNS.

Keep transactional and marketing mail operationally distinct

Password resets, account alerts, and receipts have different recipient expectations from newsletters. Use separate streams or subdomains when your provider supports them, keep consent records, and do not mix promotional content into a message that users expect to be purely transactional.

Use a recognizable From name and address, include a working reply path, and make marketing opt-out simple. For high-volume marketing, implement the provider-required list-unsubscribe headers; Yahoo specifically says a body unsubscribe link alone is not sufficient for its bulk-sender requirements. (senders.yahooinc.com)

Worked example: fixing a legitimate invoice sender sent to Spam

Imagine that billing@northwind.example sends monthly invoices through a transactional email provider. Several Gmail recipients report that invoices are landing in Spam.

Step 1: inspect a real delivered message

Ask one recipient to open the message in Gmail, select Show original, and provide the authentication summary—not account credentials or private content. You find:

SPF: PASS with IP 192.0.2.44
DKIM: PASS with domain mailer.vendor.example
DMARC: FAIL
From: billing@northwind.example

The important observation is that SPF passing alone is not enough for DMARC if the SPF-authenticated domain does not align with northwind.example. The DKIM domain also does not align with the visible From domain.

Step 2: correct alignment at the sending provider

In the provider dashboard, configure a verified custom sending domain or a DKIM signing domain under northwind.example, following that provider’s generated DNS instructions. The goal is for either:

  • SPF to pass with an aligned envelope-sender domain, such as bounce.northwind.example; or
  • DKIM to pass with a signing domain aligned to northwind.example, such as mail.northwind.example.

Do not guess the DNS hostnames or public keys. Copy the exact values issued by the provider, publish them at the authoritative DNS host, and wait for DNS propagation according to the TTL configured for those records.

Step 3: publish a monitoring DMARC record

If Northwind has no DMARC record, publish a monitored policy such as:

_dmarc.northwind.example. TXT "v=DMARC1; p=none; rua=mailto:dmarc@northwind.example; adkim=r; aspf=r"

Make sure dmarc@northwind.example can receive aggregate report mail or use a reporting service that gives you a valid rua address.

Step 4: send a new invoice test

Send a test invoice to controlled Gmail, Microsoft 365, Yahoo, and iCloud addresses. Verify:

  • The exact visible From domain is correct.
  • SPF and/or DKIM pass.
  • DMARC passes with alignment.
  • The message reaches Inbox or the expected category rather than Spam.
  • Links point to your real domain or a disclosed, trusted payment processor.
  • The message includes only the content required for an invoice, not unrelated promotional copy.

Step 5: monitor before declaring victory

One successful test means DNS and basic mail flow may be fixed. It does not prove that reputation has recovered everywhere. Monitor Gmail Postmaster Tools where eligible, complaint signals, bounces, provider event logs, and mailbox placement across your real audience. If the technical checks pass but spam placement continues, reduce unwanted volume, review list quality and consent, and remove misleading subject lines or aggressive calls to action.

Common fixes that make the problem worse

Creating a giant “never send to spam” allow list

Allow-listing an entire domain can bypass useful protection. Use exact addresses or narrowly verified domains only when the operational need is clear. Reassess these exceptions periodically.

Deleting spam instead of reporting it

Deleting cleans up your mailbox but supplies less useful feedback than reporting. Use the report function for representative samples, especially when the mail is clearly abusive.

Adding multiple SPF records

SPF is designed around a single policy record for a domain. If several platforms need authorization, consolidate their mechanisms into one valid v=spf1 record, respecting the DNS lookup constraints defined by SPF. (datatracker.ietf.org)

Publishing DMARC with p=reject before auditing vendors

DMARC enforcement is valuable, but enforcing too early can reject legitimate mail from an HR system, invoicing tool, help desk, or CRM that was not included in your inventory. Begin with monitoring, fix failures, then tighten policy deliberately.

Treating authentication as an inbox guarantee

SPF, DKIM, and DMARC are essential foundations. They do not override recipient complaints, low-quality lists, suspicious links, deceptive content, or an established poor sending reputation.

How to tell the spam filter is actually fixed

Use a measurable success condition rather than a feeling.

For a recipient-side issue, success means:

  • New obvious spam is reported and consistently lands in Spam/Junk or is blocked.
  • New messages from the trusted sender reach the intended folder.
  • No broad rule silently deletes legitimate mail.
  • The result holds across at least a few new messages, not just one old message moved manually.

For a sender-side issue, success means:

  • Headers show SPF or DKIM passing, and DMARC passing with alignment where applicable.
  • Your sending service logs show accepted delivery rather than repeated deferrals or rejections.
  • Gmail Postmaster Tools, if available for your traffic, shows authentication and delivery diagnostics for the sending domain.
  • Complaint rate and bounce behavior remain controlled as you continue to send.
  • Seed tests are useful as a smoke test, but real customer feedback and provider diagnostics do not show persistent spam-folder placement.

A healthy filter still makes mistakes occasionally. The practical goal is not “no message is ever misclassified”; it is a system in which unwanted mail is quickly reported and contained, legitimate mail is authenticated and traceable, and every exception has an explainable, limited scope.

FAQ

Why is my email spam filter not working all of a sudden?

Check whether the issue affects one sender, one mailbox, or many unrelated messages. A new inbox rule, a changed Safe/Blocked Sender entry, an administrator policy, a connected app, or a sender authentication failure can all change outcomes without the spam engine itself being disabled.

Can I turn off the spam filter completely?

You generally should not. Spam filters also help contain phishing and malicious mail. Instead, correct a specific false positive with Not spam, an exact Safe Sender entry, or a narrow filter. In a business environment, ask an administrator to make a scoped exception rather than weakening organization-wide protection.

Why does a legitimate sender go to Spam even though SPF and DKIM pass?

Authentication is necessary but not sufficient. Providers can also consider DMARC alignment, complaint signals, domain and IP reputation, content, links, list quality, and recipient behavior. Gmail’s Postmaster Tools exposes separate authentication, spam-rate, and reputation dashboards because these are distinct operational signals. (support.google.com)

Does blocking a sender stop all future spam?

Only if the sender continues using that address. Many spam campaigns rotate addresses and domains, so report the messages as spam or phishing and use narrow pattern-based rules only when a stable, trustworthy pattern exists.

How do I find a missing Microsoft 365 email?

Check Junk and quarantine, then have an administrator run message trace. Message trace can show whether the service received, rejected, deferred, or delivered the message and what happened before final delivery. (learn.microsoft.com)